1200KM / tool
Sliver — Attack Tool
Sliver is an open source, cross-platform, red team command and control (C2) framework written in Golang. Sliver includes its own package manager, "armory," for staging and downloading additional tools and payloads to the primary C2 framework.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Sliver
Existing author guides
- Lab Architecture — Operation DragonRx · 2026-05-02
- Attack Playbook — Operation DragonRx · 2026-05-04
Primary documentation
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- APT29 · G0016 · Pinned relationship source (relationship--ed096691-23a6-4104-879d-5e96d257b3f0)
- TA551 · G0127 · Pinned relationship source (relationship--919ed248-2736-4024-9f0b-001c23a85d82)
- Cinnamon Tempest · G1021 · Pinned relationship source (relationship--1a0bc35b-cc76-487b-a1a7-71cbfb110f24)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1001.002 · Steganography · Detection rules & anomalies
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1027.004 · Compile After Delivery · Detection rules & anomalies
- T1027.013 · Encrypted/Encoded File · Detection rules & anomalies
- T1041 · Exfiltration Over C2 Channel · Detection rules & anomalies
- T1049 · System Network Connections Discovery · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1071 · Application Layer Protocol · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1071.004 · DNS · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1090.001 · Internal Proxy · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1113 · Screen Capture · Detection rules & anomalies
- T1132.001 · Standard Encoding · Detection rules & anomalies
- T1134 · Access Token Manipulation · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1558.001 · Golden Ticket · Detection rules & anomalies
- T1573.001 · Symmetric Cryptography · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Credential Request · DC0084
- Active Directory Object Modification · DC0066
- Application Log Content · DC0038
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Firewall Rule Modification · DC0051
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
- Script Execution · DC0029
- Service Creation · DC0060
- User Account Metadata · DC0013
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.